Published August 11, 2026 · Facts last verified August 11, 2026
This article is general information, not legal, medical or clinical advice. For advice about your own situation, consult a qualified professional. If you are in immediate danger, contact your local emergency number — in the US, call or text 988; elsewhere, findahelpline.com lists free crisis lines by country. Nothing here is a reason to delay asking a human for help.
The reasons people give are almost always the same three. It is available at two in the morning, which is when the thoughts arrive. It costs nothing, against a waiting list measured in months. And it does not react — no flicker of surprise, no follow-up appointment, no face you have to watch while you say the thing you have never said out loud.
Those are good reasons, and this article is not going to pretend otherwise. What it is going to do is describe, precisely, what the exchange leaves behind — because an emotional conversation is the most revealing thing most people will ever type into a computer, and the rules that protect it in a consulting room do not travel with it into a chat window.
This Is Not a Fringe Behaviour
The numbers were published by the companies themselves, which is what makes them worth quoting.
In October 2025, OpenAI released an analysis of ChatGPT traffic alongside a set of safety improvements. Its estimates: around 0.15% of users active in a given week have conversations containing explicit indicators of potential suicidal planning or intent, and about 0.05% of messages carry explicit or implicit indicators of suicidal ideation. Roughly 0.07% of weekly users show possible signs of a mental health emergency related to psychosis or mania, and a further 0.15% show possible signs of heightened emotional attachment to ChatGPT itself. Against a user base the company put at around 800 million weekly, those fractions describe well over a million people a week.
Among teenagers it is not an edge case at all. Common Sense Media's nationally representative survey of 1,060 US 13- to 17-year-olds, published in July 2025, found that 72% had used an AI companion and 52% used one regularly; about a third had turned to one instead of a person for a serious conversation, 12% had told one things they would not tell friends or family, and 31% found the conversations as satisfying as — or more satisfying than — talking to a real friend.
Among adults, a KFF poll fielded in early 2026 found roughly one in six had used AI chatbots for mental health information in the past year, with under-30s about three times more likely to do so than the over-50s. We covered that poll, and the physical-health side of the same behaviour, in asking AI about health symptoms.
So: a large, sustained, mostly private behaviour, conducted by people who are — the surveys are consistent on this — quite aware that it is being recorded, and who do it anyway. Which means the useful thing to write is not a warning. It is an inventory.
What You Are Actually Giving Up
Confidentiality in therapy is not a courtesy or a company policy. It is a stack of separate legal instruments, and it is worth seeing them itemised, because the chat window has none of them.
An evidentiary privilege. In Jaffee v. Redmond, 518 U.S. 1, decided June 13, 1996, the US Supreme Court recognised a psychotherapist–patient privilege in federal courts — noting in its reasoning that all fifty states and the District of Columbia had by then enacted some form of it. The privilege has elements: the communication must be confidential, it must be made in the course of diagnosis or treatment, and the other party must be a licensed psychotherapist. A chatbot fails the third element before anyone reaches the first two. There is no version of this argument that a general-purpose AI product wins.
A special category inside health privacy law. Under the US HIPAA Privacy Rule, psychotherapy notes — the notes documenting or analysing the contents of a counselling session, kept separate from the rest of the medical record — get treatment no other clinical record gets: as a rule they cannot be disclosed without the patient's specific authorisation, and that authorisation cannot be bundled with any other (45 CFR 164.508). The profession decided, and the regulation agreed, that the transcript of the room is categorically different from the chart. Note what that implies about a chat log, which is the transcript of the room, verbatim.
A professional bound by all of it. A licensed clinician carries duties enforced by a licensing board, by insurers, and by the possibility of losing their career. An AI company carries terms of service it wrote and may revise.
And HIPAA itself does not reach the conversation at all — it follows covered entities and the business associates they hire, not health information as such, so a chat between you and a chatbot sits outside the law rather than being weakly protected by it. We work through that in detail in the health-symptoms article, and from the clinician's side in is ChatGPT HIPAA compliant?
In July 2025, Sam Altman said the quiet part plainly: people talk to ChatGPT about intensely personal problems the way they would talk to a therapist or a lawyer, and unlike those conversations there is no privilege and no equivalent of doctor–patient confidentiality, so the company could be compelled to produce the records. Nothing since has changed that.
The Record Is Worse Than a Clinical File — and That Is Not Hyperbole
Compare the two artefacts honestly.
A therapist's file is a professional's summary. Someone trained to decide what matters wrote down a fraction of what you said, in clinical language, for a clinical purpose. Everything else evaporated in the room.
A chat log is the opposite in every respect:
- Verbatim, and in your own voice. Not "patient reports conflict in the marriage" but the sentence you actually typed at 3:40 a.m., including the part you regretted.
- Complete. Nothing was filtered out as clinically irrelevant, because nothing was filtered at all.
- Timestamped. The pattern of when you write is itself a mental health record: a cluster of messages every night for three weeks in March says something that no sentence inside them says.
- Longitudinal. Where a session ends, a thread continues. Months of it, in one searchable place, with the model's own summaries layered on top.
- Full of other people. Your partner by name, your child's diagnosis, what a colleague did, what a parent said in 2007. None of them consented, and in Europe you may well be processing their data as a controller when you type it (see the erasure article for what that machinery does and does not reach).
- Full of admissions. This is the category people miss. Emotional conversations routinely contain disclosures whose consequences have nothing to do with therapy: substance use, an affair, something done at work, a debt, an immigration status.
- Wrapped in metadata. Account, device, IP, timing — the envelope stays legible even when the letter is deleted (the prompt metadata problem).
There is no equivalent object anywhere else in an ordinary life. Not a diary, which nobody indexes. Not a search history, which is keywords. This is prose, written under emotional pressure, attached to a verified identity.
Who Can Read It — the Accurate Answer
Almost nobody is reading your chat right now, and articles implying otherwise are wrong. The accurate answer is layered, and the layers matter.
Classifiers read everything. Automated safety systems evaluate messages as a matter of course. That is not a scandal; it is how a crisis response gets triggered at all.
Some conversations are routed to people — and the mental health ones are the most likely to be. In August 2025 OpenAI described its process: conversations indicating that someone is planning to harm others go to specialised pipelines reviewed by a small team trained on its usage policies, and where reviewers find an imminent threat of serious physical harm to others, the case may be referred to law enforcement. In the same breath the company said it is not currently referring self-harm cases to law enforcement, "to respect people's privacy given the uniquely private nature of ChatGPT interactions."
Read that as good news, and then read the word currently. It is a policy, written by the party it constrains, revisable at that party's discretion, and describing exactly one company. The structural fact underneath it does not move: to detect a crisis, a system must be able to inspect the conversation, and a conversation that has been flagged is a conversation designed to be human-readable.
There is a genuine tension here that nobody in this debate likes to state, so we will: the safety features are the inspection features. They exist for defensible reasons — the harms they respond to are real and documented — and they are simultaneously the mechanism by which the most private conversation a person has ever had becomes an escalated case file. Both halves are true. Anyone offering you only one of them is selling something.
Where the Record Goes Next
Into litigation, including litigation you are not part of
Chat logs have already been the central evidence in cases about chatbots themselves. In Garcia v. Character Technologies (M.D. Fla.), the wrongful-death claim brought after a fourteen-year-old's suicide, the conversations were the heart of the record; the judge allowed most of the claims to proceed in May 2025, and the case settled, with the settlement order entered January 7, 2026 and terms undisclosed. In Raine v. OpenAI, filed August 26, 2025 in San Francisco Superior Court, the same is true from both directions: the complaint quotes the conversations at length, and OpenAI's November 2025 answer — denying responsibility — argued from that same transcript that ChatGPT had directed the teenager to crisis resources more than a hundred times. Whatever one makes of the merits, note the mechanism. The most private conversations of a person's life became a public exhibit, quoted by opposing lawyers.
You do not have to be in a lawsuit for this to reach you, either. In the New York Times litigation against OpenAI, a May 2025 preservation order required the company to retain output logs that would otherwise have been deleted, and in January 2026 the court affirmed production of a 20-million-conversation de-identified sample of consumer chats from December 2022 to November 2024. Inclusion turned on whether a conversation was retained and fell within that dataset and date range — not on its subject matter, and not on anything about the user. Nobody was notified; nobody got to object. The chronology is in can your AI chats be subpoenaed?, and the everyday version — divorce, custody, employment disputes — in when AI chat logs show up in a lawsuit.
One point of precision, because it is widely misreported. Several US courts in 2026 have shielded a litigant's AI chats as work product — a doctrine about material prepared in anticipation of litigation, with its own conditions and its own ways of being lost. That is not a confidentiality for personal conversations, and it is not privilege. In the criminal case that started the line, United States v. Heppner (S.D.N.Y., Judge Rakoff, February 10, 2026), the court held that protection never attached to a defendant's Claude conversations — reasoning, among other things, that the consumer terms he had accepted defeated any reasonable expectation of confidentiality. The terms are not a formality. A court read them and drew a conclusion about a user's expectations from them. We unpack it in AI and attorney–client privilege.
Into a breach — the category with the worst precedent of any
Mental health records are not merely sensitive. They are the most efficiently extortable personal data that exists, and this has been demonstrated at scale.
The Finnish psychotherapy provider Vastaamo was breached in 2018; the treatment records of roughly 33,000 patients were taken. When the company refused to pay, the attacker went to the patients individually, demanding a few hundred euros each not to publish their session notes — and published data anyway. Finnish police reported that around 22,000 people received an extortion attempt. In April 2024 a district court convicted Aleksanteri Kivimäki on thousands of counts of aggravated dissemination of information violating private life and aggravated attempted blackmail, sentencing him to six years and three months. The victims had done nothing except attend therapy.
The AI-companion equivalent has already happened, with worse engineering. In October 2025 Cybernews researchers reported that two companion apps, Chattee Chat and GiMe Chat, had exposed more than 43 million private messages and over 600,000 images and videos from roughly 400,000 users — through a Kafka broker left open with no authentication at all. Not a sophisticated attack. A missing password on the pipe carrying everything users said to their AI partners. What a provider breach exposes more generally is in this article.
Into a profile that outlives the mood
The third path is the quietest. Memory features summarise what you disclose into a persistent, portable description of you, then apply it in unrelated conversations weeks later. Training scatters words into a statistical average; memory does the opposite and concentrates them into a compact, readable account of a person — charming when it recalls your coffee order, something else entirely when it recalls a diagnosis while helping you draft a cover letter. Our argument is in AI memory is a privacy time bomb.
And the holder can change. Companies are acquired, wound up, or sold in proceedings you are not party to, under terms you never agreed to. A period in your life ends; a record of it does not.
The Law Is Arriving — for the Bot, Not for the Transcript
Regulation of AI in mental health moved faster in 2025 and 2026 than almost anywhere else in AI policy. It is worth knowing what it does, and what it conspicuously does not.
- Illinois — the Wellness and Oversight for Psychological Resources Act (HB 1806, Public Act 104-0054), signed August 1, 2025, bars offering therapy or psychotherapy services to the public unless conducted by a licensed professional, and bars AI from making independent therapeutic decisions or engaging in therapeutic communication without licensed review. Violations carry fines of up to $10,000, enforced by the state's Department of Financial and Professional Regulation.
- Nevada — AB 406 (2025) prohibits AI systems from providing professional mental or behavioural health care and restricts marketing a service as AI therapy or an AI counsellor.
- Tennessee — SB 1580, effective July 1, 2026, prohibits AI systems from presenting themselves as licensed mental health professionals.
- California — SB 243, effective January 1, 2026, regulates companion chatbots: disclosure that the user is talking to a machine, crisis-response protocols, and specific protections for minors.
- New York — General Business Law Article 47, in force since November 2025, requires AI companions to detect expressions of suicidal ideation or self-harm and refer users to crisis services, alongside recurring disclosures.
- Oregon — SB 1546, effective January 1, 2027, adds suicide-risk detection, crisis referrals, annual filings and a private right of action with statutory damages.
- The FTC opened a Section 6(b) study on September 11, 2025 into seven companies offering AI companion products — Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and xAI — covering safety, monetisation and data handling, with particular attention to minors. A 6(b) study is a study, not an enforcement action, and no public report had been issued as of this writing.
- In the EU, since 2 August 2026 Article 50 of the AI Act requires systems that interact directly with people to be designed so users are informed they are dealing with a machine, unless that is obvious. Mental health data is a special category under Article 9 of the GDPR, which prohibits processing in principle unless an Article 9(2) exception applies — for a consumer app, normally your explicit consent. That conditions the processing and adds duties; it does not stop it. (The AI Act's ban on emotion recognition is narrower than people assume: it covers workplaces and educational settings, not consumer chatbots.)
- Enforcement that was actually about data: Italy's Garante fined Luka Inc., developer of the companion app Replika, €5 million — decision adopted April 10, 2025, announced May 19, 2025 — for processing personal data without a valid legal basis and failing to prevent access by minors, and opened a further investigation into how the underlying model was trained.
Now the pattern. Nearly all of it governs how the system behaves inside the conversation: what it must disclose, what it must not claim to be, what it must do when someone is in danger. Almost none of it gives the transcript anything like the status a therapy record has — no privilege, no special-authorisation rule, no professional bound to it. And several of these statutes, entirely reasonably, require providers to detect crisis language, which is to say they require inspection. The law is making these products safer. It is not making them confidential.
One consequence is already visible in the market: providers are narrowing the behaviour rather than the data collection. Character.AI removed open-ended chat for under-18 users in the US in late November 2025 — a real change, and a change to what the bot does, not to what the logs are.
Getting the Value Without Building the Record
None of this argues for not using the tool. Used deliberately it is genuinely useful: it explains what a diagnosis means, rehearses a conversation you are dreading, produces the questions to bring to an actual appointment, and gets you through a night. The goal is to keep that value while lowering how much of you is attached to it.
First, and before anything technical: if you are in crisis, this is the wrong thing to optimise. Call a human — 988 in the US, or a local line via findahelpline.com. Privacy is worth protecting on ordinary days, not worth weighing against your safety on the worst one.
On ordinary days:
- Separate the two things you might want. Understanding, technique and rehearsal can be asked about in general terms and answered just as well. Being known — the accumulated, specific, longitudinal account of you — is the part that builds the record, and it is the part no product can legally protect.
- Describe the situation, not the cast. No names, including your own. "My partner" rather than a name; "a colleague" rather than a job title at an eleven-person company. Other people's details are theirs to disclose, and naming them is the commonest way a chat stops being about only you.
- Keep the three identifiers apart — employer, city, and any rare specific (an unusual diagnosis, a date, a case number). Any one of them is harmless; the combination is often unique.
- Do not upload the documents. An assessment, a discharge summary, a court filing or a screenshot carries your full name, date of birth and record numbers in the parts you are not reading, plus the file's own metadata (what is inside an uploaded file). Type the two sentences that matter instead.
- Turn the persistence off before you start. Memory off, training off, temporary mode entered before the first message rather than three messages in — see the settings checklist, the fine print of temporary chat, and how to opt out of training.
- Never on a work or school device. Managed endpoints, enterprise browsers and monitoring tooling can log the prompt itself as searchable text, and an employer is the party whose knowledge of your mental health has the most direct consequences (what your IT department can see).
- Decide deliberately what you keep. A local transcript is yours, which is better — and an unencrypted export of months of emotional conversation is one of the most dangerous files you will ever own (exporting and backing up safely).
- Point it at the highest-value use. Ask it to prepare you for a real appointment. It is very good at that, and it needs almost none of the disclosure that the "just talk to it" mode invites.
A framing that keeps the conversation on the problem instead of on the person:
I want to think through a difficult personal situation without giving you any identifying details about me or anyone else. Please help me understand what is going on, suggest concrete coping approaches, and list the questions I should bring to a professional. Do not ask for my name, location, employer or anything else that identifies me, and refer to the people involved only by their role. Here is the situation, described in general terms:
Where Secret Chat AI Fits — and Where It Doesn't
Look back at that list and notice what every item has in common: it is you being careful inside a product that knows exactly who you are. The account, the email, the payment method and the device stay attached to every message. There is no setting anywhere labelled stop associating this with me.
That missing setting is what Secret Chat AI is built to be. It is an anonymizer and depersonalizer, and the design is deliberately narrow: no profile, no association, no training.
- No profile of you. Registration takes an email, used only for account access and payment — never to store or associate your prompts with you. No behavioural profile is assembled across your chats, which is the mechanism by which one bad night otherwise becomes a durable attribute of a person.
- No chat associated with you. Requests reach the leading models through their business APIs under our gateway's credentials, from our servers. Whatever a model provider holds under its own terms and configuration, the record on that side carries our credentials and server address — not your name, your account or your IP. You use the model as a stranger.
- Nothing kept under your name. Chat history lives in your own browser, and a prompt exists on our side only for as long as it takes to fetch your answer — there is no stored chat archive on our servers. Each message gets a Session Privacy Report.
- No training. Your queries are never used to train models.
Now the boundaries, which for this topic matter more than the claim.
It is an anonymizer, not a content filter. "Anonymously" describes the link, not the words: no account identifier travels with your prompt, but the text is not altered, redacted or hidden — the provider reads exactly what you wrote in order to answer it. Write your own name, your therapist's name or your employer into a message and it is all still sitting there in the message. Removing identifying details before you send is yours to do. What we remove is who is asking; what is being asked is still up to you.
It is not confidentiality, and it is not privilege. Anonymity does not create a psychotherapist–patient relationship, does not make anything privileged, is not a legal exemption, and is not a way to hide anything a court is entitled to. Nobody's own duty to preserve relevant material changes because of the tool they used.
It is not care, and it is not an emergency service. An anonymous conversation with a very capable model is still a conversation with a model. It cannot notice you across a room, it carries no duty toward you, and it is not the thing to reach for when the situation is acute.
Frequently Asked Questions
- Is my conversation with an AI about my mental health confidential?
Not in the legal sense. Therapeutic confidentiality rests on instruments a chatbot does not satisfy: the psychotherapist–patient privilege recognised in Jaffee v. Redmond (1996) requires a licensed psychotherapist, and HIPAA's special rule for psychotherapy notes applies to records held by covered entities. A consumer AI conversation has neither. As OpenAI's chief executive put it publicly in July 2025, there is no privilege and no equivalent of doctor–patient confidentiality for these chats, and the company could be required to produce them.
- Can an AI company report me to the police if I say I want to hurt myself?
Under OpenAI's stated policy, no — the company said in August 2025 that it is not currently referring self-harm cases to law enforcement, citing the uniquely private nature of the interactions. Conversations indicating a plan to harm others are treated differently: they are routed to a small trained review team and may be referred to law enforcement where reviewers find an imminent threat of serious physical harm. Two caveats: that is one company's policy rather than a law, and the word "currently" is doing real work. Structurally, crisis-detection features mean these are exactly the conversations most likely to be seen by a person.
- Do the new state laws on AI therapy protect my chat data?
Mostly they protect the interaction, not the transcript. Illinois' 2025 Act bars AI from delivering therapy without a licensed professional, Nevada's AB 406 bars AI from providing professional behavioural health care, Tennessee's SB 1580 bars AI from presenting as a licensed mental health professional, and California's SB 243 and New York's Article 47 require disclosure, crisis protocols and protections for minors. None gives a chat log the status of a clinical record, and several require providers to detect crisis language — which necessarily means inspecting conversations. In the EU, mental health data is a special category under GDPR Article 9, which conditions the processing rather than preventing it.
- Could my emotional conversations end up in court?
Yes, by more than one route. They can be requested in your own litigation — divorce and custody proceedings are the common case — and they have already been the central evidence in cases about chatbots themselves, including Garcia v. Character Technologies (settled, order entered January 7, 2026) and the pending Raine v. OpenAI, where both sides quote the transcript. You can also be reached without being a party: a May 2025 preservation order in the New York Times case required OpenAI to retain logs that would otherwise have been deleted, and a 20-million-conversation sample was later produced, with no notice to the users involved. Note that the 2026 rulings shielding some AI chats did so as work product — a litigation doctrine — which is not a general confidentiality.
- Does deleting the conversation undo it?
It removes it from your visible history, which is not the same thing. Memory entries are usually deleted separately from conversations, retention windows run on the provider's clock, anything already absorbed into training is not retrievable, and a legal preservation order overrides the delete button outright. Deleting also does nothing about the copy on a work device or in an export you saved.
- What is the safest way to use AI for emotional support?
Treat it as a thinking and preparation tool rather than a confessional: describe the situation without naming anyone including yourself, keep employer, city and rare specifics out of the same conversation, type the two relevant sentences rather than uploading documents, turn memory and training off and start in temporary mode, and never do it on a work device. Using a service that reaches the models without your identity attached — Secret Chat AI — removes the association; keeping identifiers out of the text is still your part. And if the situation is acute, call a crisis line or emergency services instead: 988 in the US, or a local line via findahelpline.com.
Conclusion
There is a version of this article that ends by telling you to stop. It would be dishonest. People are not doing this at two in the morning because they are careless about privacy — the surveys show they are unusually aware of it — but because the alternative available at two in the morning is nothing.
What is worth changing is the shape of what gets left behind. A therapy hour produces a professional's summary, held by someone bound to it. An hour with a chatbot produces a complete, verbatim, timestamped, searchable account of your worst night, attached to a verified identity, governed by terms rather than by law — and a court has already reasoned from terms like those that expecting confidentiality was unreasonable.
Two of the three components of that are yours to change. Keep the identifying details out of the text, and use a route that does not attach your identity to the request. Then what survives is a conversation about a problem, rather than a file about a person.
Ask the question. Just ask it as a stranger — and when it is more than a question, ask a human.
Sources
- OpenAI — Strengthening ChatGPT's responses in sensitive conversations (October 27, 2025)
- ABC7 News — OpenAI data estimates over 1 million people talk to ChatGPT about suicide weekly
- OpenAI — Helping people when they need it most (August 26, 2025)
- Futurism — OpenAI on reviewing conversations and referring threats against others to law enforcement
- Common Sense Media — Talk, Trust, and Trade-Offs: nearly 3 in 4 teens have used AI companions (July 2025)
- KFF — Poll: 1 in 3 adults are turning to AI chatbots for health information (fielded February–March 2026)
- US Supreme Court — Jaffee v. Redmond, 518 U.S. 1 (1996)
- eCFR — 45 CFR 164.508, authorisation requirements including psychotherapy notes
- HHS — HIPAA Privacy Rule and sharing information related to mental health
- Illinois IDFPR — Governor signs legislation prohibiting AI therapy (HB 1806, August 2025)
- Baker Donelson — Illinois passes extensive law regulating AI in behavioral health
- Orrick — 2026 state chatbot laws: key provisions and regulatory trends
- FTC — Inquiry into AI chatbots acting as companions (September 11, 2025)
- EUR-Lex — EU AI Act, Regulation (EU) 2024/1689 (Article 50 transparency)
- EUR-Lex — GDPR, Article 9 (special categories of personal data)
- Buchanan Ingersoll & Rooney — Italy's Garante fines the developer of Replika €5 million
- Krebs on Security — Man who mass-extorted psychotherapy patients gets six years (Vastaamo)
- Cybernews — AI companion app leak exposes 400,000+ users and their conversations
- Malwarebytes — Millions of very private chats exposed by two AI companion apps (October 2025)
- Character.AI — Taking bold steps to keep teen users safe (removing open-ended chat for under-18s, November 2025)
- NBC News — OpenAI denies allegations in the Raine wrongful-death lawsuit (November 2025)
- TechCrunch — Sam Altman warns there's no legal confidentiality when using ChatGPT as a therapist (July 25, 2025)
- OpenAI — Response to the New York Times data demands (preservation and production scope)
- 988 Suicide & Crisis Lifeline (US)
- Find a Helpline — free crisis lines by country